成长值: 62320
|
题目不是很完整,答案仅供参考
' E5 K6 I0 h* y& w* n2 \+ V
D" ~1 l8 m$ X4 LQuestion 01:, ^0 i9 R! O' t$ J8 Y4 L, [
Witch access list entry checks for an ACK within a packet header?. Z2 U+ ~) g* h, A( R7 L
A access-list 49 permit ip any any eq 21 tcp-ack
- B4 n" d0 r4 Y0 W. k8 k {B access-list 49 permit tcp any any eq 21 tcp-ack/ G3 o. J: ~2 o: ?/ ?* ~* C; P
C access-list 149 permit tcp any any eq 21 established
2 K* H3 W+ ~% A: I2 f- fD access-list 49 permit tcp any any eq 21 established' l1 y, f5 ?+ ]
Ans: C
+ X- ] O$ u, @3 ^8 H/ c5 W———————————————————————————
) p' `% h' W# Y* rQuestion 02: B% A7 m9 k$ [
Which option is one way to mitigate symmetric routing on an active/active firewall setup for TCP-based connections?
! `8 G2 B" B4 `" c: pA performing packet captures
3 B6 m6 b7 u, G6 H! ?' h2 K5 y+ _B disabling asr-group commands on interfaces that are likely to receive asymetric traffic9 B4 S) W( N8 U* D: W* P# b
C replacing them with redundant routers and allowing load balancing! Q1 @# h. n. V5 v" y: \
D disabling stateful TCP checks1 {& p& k5 f3 y! x; R
Ans: D- q% l( B- T' e
3 e( K6 z# m; {6 x( Z4 ~
[' |( J( s& n1 v! R1 D) e |
|